Dialing Up a Scam: Avoiding the Auto-Dialer Virus

For many, the daily walk to the mailbox evokes mixed feelings: The glee that your favorite monthly magazine ? or a friend's hand-written letter (quite a surprise in the e-mail age) may be waiting is countered by anxiety of how many bills the postman left you.

Now, imagine coming across your phone bill, thicker and heavier than normal. When you open it, instead of "statement stuffers" from the phone company's marketing department, the bill is dozens of pages long ending in a one-month total of almost $5,400.

A quick glance at the details reveals hundreds of calls to the same 1-900 number. "A mistake," you insist. After all, you're the only person in the house and you have never called a 900 number before. Actually, this is no mistake. In this true story, the homeowner had fallen victim to one of the oldest computer scams around: the "Auto-Dialer" virus.

How Did This Computer Security Nightmare Begin
-----------------------------------------------------------
What is an "auto-dialer"? Some time ago, the phone companies came up with a feature that allowed merchants to reach a broader range of customers by allowing consumers to make payments via your phone bill. If you did not have a credit card, you just dialed a 900 number, connected by voice or modem (for Internet sites). Every minute you used the service, you were charged a fee ranging from $1 to $5 or more per minute. At month's end, the charge appeared on the phone bill. Many services were legit: Consumers called weather, horoscope and gambling services offering this feature. But many merchants sold expensive phone or online adult content.

How Did An Auto-Dialer Get Installed
-----------------------------------------------------------
But how did $5,400 in charges end up on the person's phone bill? Although many of these services require the user to physically dial the number or connect to the online site by instructing the modem to dial the number, this can happen without the user's knowledge. In the above case, the person's computer was infected with an auto-dialer virus. Somewhere during his Web travels, he connected to a site that popped up a rather confusing message instructing him to "Hit OK" to make the message go away. What this person didn't know was he was agreeing to download,install, and execute an adult content auto-dialer.

Behind the scene, the auto-dialer installed itself, checked for the presence of a modem and dial tone, and then proceeded to dial an overseas 900 number over and over again. Even though the person surfed using an always-on broadband Internet connection, the modem remained so he could send and receive faxes. One problem: When he wasn't using the modem, it remained plugged into the phone jack. Why should he have unplugged it? It's not like it could hurt anything, right? Wrong.

How To Protect Yourself
-----------------------------------------------------------
Unfortunately, there is no single solution to avoid these types of malicious acts. A short list of protective measures would include:

1) If you no longer need a modem in your computer, remove it. Or at least disconnect the phone line from the modem;

2) Install anti-virus software such as Trend Micro or Symantec's Norton Anti-Virus. Many are designed to prevent this kind of malicious software, or "Malware." More importantly, make sure your subscription for new virus patterns is current and configured to automatically download and install updates;

3) Install and regularly run Adware protection solutions such as LavaSoft's Ad-Aware or SpyBot Search & Destroy;

4) And do not, under any circumstances, blindly hit "OK" to pop-ups or similar annoyances without first making sure what you are agreeing to.

This tale is not fiction; in fact, it happens frequently, to businesses and consumers, kids and adults. But even the least savvy among us can thwart such an attack. A neighborhood teenager recently avoided potentially thousands in fees when an auto-dialer was downloaded and installed. How? She had unplugged the modem.


About The Author
----------------
Darren Miller is an Industry leading computer and internet security consultant. At the website - http://www.defendingthenet.com you will find information about computer security specifically design to assist home, home business and small business computer users. Sign up for defending the nets newsletter and stay informed and empowered to stay safe on the Internet. You can reach Darren at mailto:darren.miller@paralogic.net or at mailto:defendthenet@paralogic.net
URL
---
http://www.defendingthe net.com/NewsLetters/Auto-Dialer-Newsletter.htm

In The News:


Hot Hardware

Number Of Bank Customers Affected By Security Breach Soars
Hartford Courant, United States - 14 hours ago
New York Mellon disclosed in May that the security breach affected 497333 Connecticut residents, most of them depositors of People's United Bank in ...
Security breach at bank hits 12M people: BNY Mellon records could ... TMCnet
Bank of NY Mellon says data breach now affects 12M CNNMoney.com
Bank of NY Mellon data breach now affects 12.5 mln Reuters
SC Magazine UK - Dark Readingall 49 news articles

dBTechno

iPhone Round-Up: Security Fix; Rogers Revamps Prices; AT&T ...
Washington Post, United States - 22 hours ago
Security Flaw and repair date: A recently discovered security flaw will be fixed by September, Apple ( NSDQ: AAPL) told Macworld today. ...
Network Security Apple Won't Fix iPhone Passcode Hole Until September CIO Today
Apple promises September fix for iPhone security flaw Macworld
Apple To Fix iPhone Security Flaw CRN
ChattahBox - eFluxMediaall 122 news articles

Tight Security, Festive Atmosphere Await Convention Travelers at ...
MarketWatch - 2 hours ago
A new pre-security Houlihan's opened this week in the Lindbergh Terminal Ticketing Lobby, near Checkpoint 1. The full-service restaurant is accessible to ...

Homeland Security Capital Corporation's Environmental Remediation ...
MarketWatch - 11 hours ago
an international provider of specialized technology-based radiological, nuclear, environmental, disaster relief and security solutions to government and ...

Proctor & Gamble outsources security to IBM, but keeping security ...
NetworkWorld.com, MA - 8 hours ago
"By teaming with IBM ISS, our objective is to both strengthen our security systems and improve the efficiency and effectiveness of our security operations," ...
Procter and Gamble Selects IBM Internet Security Systems to Help ... CNNMoney.com
Proctor & Gamble Taps IBM ISS For Cyber-Security Contract InformationWeek
Proctor & Gamble Chooses IBM ISS for Cyber Security IT Business Edge
Bizjournals.comall 18 news articles

ABC News

Communiques from the security front, sir
ZDNet UK, UK - Aug 28, 2008
... easy it was to break into the Nasa systems, or, to quote his dad when I spoke to them both outside the House of Lords in June -- "The security was crap. ...
Space station computer virus raises security concerns New Scientist (subscription)
The IT Security of the ISS Wired News
Ground Control To Major Tom: Check Your Laptop For Worms CRN
InternetNews.comall 216 news articles

Bank security guard is shot and killed in South LA
Los Angeles Times, CA - 15 hours ago
Two attackers wrested a handgun from a security guard at a Los Angeles bank Thursday, then fatally shot him with his own weapon, police said. ...
New info in security guard shooting case abc7.com
Bank Security Guard Shot, in Critical Condition After Robbery MyFox Los Angeles
Security Guard Shot Outside Bank Dies KTLA
Los Angeles Times - Los Angeles Timesall 6 news articles

eFluxMedia

Apple to Fix iPhone Security Loophole
InternetNews.com - 4 hours ago
An Apple spokesperson told Reuters via e-mail that Apple was aware of the iPhone security flaw and is preparing a software update to fix the flaw, ...
IPhone security flaw allows bypassing of password San Francisco Chronicle
Hold On To Your iPhones, Apple Says Fix On The Way CRN
iPhone Suffers From Major Security Bug eFluxMedia
CNET News - VNUNet.comall 40 news articles

Fixing Social Security
Washington Post, United States - 20 hours ago
25 editorial "Social Security on Ice" about Democratic presidential nominee Barack Obama's suggestion of a higher FICA tax on earned income of more than ...
We Cannot Tax Our Way out of the Entitlement Crisis American Enterprise Institute
Deficit Hawks Rain on Obama’s Parade CQPolitics.com
all 3 news articles

Boston Globe

Zardari moves into PM's House over security concerns
Hindu, India - 10 hours ago
Islamabad (PTI): Pakistan's presidential front- runner Asif Ali Zardari has moved into the heavily-guarded Prime Minister's House over security fears in the ...
Zardari staying at PM House for ‘security reasons’ Newspost Online
Musharraf eyes comfy retirement home The Associated Press
Pakistan's presidential favorite under guard The Associated Press
all 641 news articles
security - Google News

Email Hoaxes, Urban Legends, Scams, Spams, And Other CyberJunk

The trash folder in my main inbox hit 4000 today. Since I never throw anything... Read More

Do You Know What your Kids Are Doing Online?

It's a sad statistic, but hundreds of unsuspecting kids are lured away from home every... Read More

Breaking Into Your PC: News...

You'd better learn news from media, not from emails, security experts warn us users again.Numerous... Read More

Identity Theft - Dont Blame The Internet

Identity theft ? also known as ID theft, identity fraud and ID fraud ? describes... Read More

Click Here To Defeat Evil

Microsoft routinely releases new security updates, many of which are given it's highest severity rating... Read More

Securing Your Accounts With Well-Crafted Passwords

In the past I've never really paid much attention to security issues when it comes... Read More

Corporate Security for Your Home Business

The words Corporate Security may conjure up images of a group of techies working in... Read More

Social Engineering - The Real E-Terrorism?

One evening, during the graveyard shift, an AOL technical support operator took a call from... Read More

Beware of Imitations! Security, Internet Scams, and the African Real Estate Agenda

Fishing on the Internet has come a long way. However, we TechWeb junkies like to... Read More

Phishing, Fraudulent, and Malicious Websites

Whether we like it or not, we are all living in the Information Age. We... Read More